Free GPEN practice test — 298+ GPEN practice questions with detailed explanations across all 15 official GPEN exam domains. Every set is scored and drawn from the live question bank — so you practise exactly what the exam tests, not outdated dumps.
Courseiva includes 298+ GIAC Penetration Tester practice questions across the official exam domains.
Feature
Courseiva
This free GPEN practice test mirrors the structure and difficulty of the real GIAC Penetration Tester exam. Every question is written against the official 2026 exam blueprint published by GIAC, ensuring you practise exactly what the exam tests — not last year's objectives.
The GPEN blueprint is divided into 15weighted domains. Questions on this page are distributed proportionally across each domain, so the mix you see here reflects the same weighting you'll face on exam day. High-weight domains like Attacking Password Hashes and Password Attacks and Formats contribute the most questions, meaning focused practice on these areas gives you the highest return on study time.
GPEN Exam Blueprint — 15 Domains
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning
23 numbered sets, 15 domain question banks, and targeted sessions — every page is a unique set of questions.
Choose all correct answers
Each chapter page covers one topic in depth — theory, key concepts, and focused practice questions. Use these to close knowledge gaps before returning to full practice tests.
Getting the most from practice questions requires more than just clicking through answers. Here is the study method used by candidates who pass GPEN on their first attempt:
Answer before revealing
Read each GPEN question fully, eliminate obviously wrong choices, then commit to an answer before clicking to reveal. This active recall process is what builds lasting knowledge.
Read every explanation
Even when you answer correctly, read the full explanation. Knowing WHY the right answer is correct — and why the distractors are wrong — is what separates a 750 score from a 900 score.
Track weak domains
Note which GPEN domains you get wrong most often. Then do a targeted 20-30 question session focused only on that domain until your accuracy improves.
Simulate exam pacing
The real GPEN is 90 minutes long. Use timed sessions to build the concentration and pacing you will need on exam day.
Most candidates who pass GPEN on their first attempt report doing between 400 and 800 practice questions over 4–8 weeks of preparation. With 298+ questions in the Courseiva bank, you have more than enough material to build that repetition without seeing the same question twice.
Answer each question to reveal the full explanation and correct answer. This starter set is drawn from all 15 exam domains in blueprint proportion. Use the session selector to start a longer focused practice run.
During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform an offline brute-force cracking attack against the captured hash using Hashcat. Which specific Hashcat attack mode and hash format identifier must be specified to successfully crack this captured challenge-response pair?
Select an answer to reveal the explanation
What is the main risk associated with storing cleartext credentials in environment variables or configuration files?
Select an answer to reveal the explanation
Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?
Select an answer to reveal the explanation
Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?
Select an answer to reveal the explanation
Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?
Select an answer to reveal the explanation
A penetration tester is reviewing Kerberos traffic and notices that a user account has the DONT_REQ_PREAUTH flag set in its userAccountControl attribute. The tester wants to obtain crackable material for this account without any domain credentials. Which technique should the tester use?
Select an answer to reveal the explanation
You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?
Select an answer to reveal the explanation
Which of the following is the most effective way to detect C2 beacons that use jitter and randomized timing?
Select an answer to reveal the explanation
During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?
Select an answer to reveal the explanation
During an internal penetration test, an attacker compromises a standard user account in a hybrid Azure AD environment. The organization synchronizes on-premises identities using Azure AD Connect with Pass-Through Authentication enabled. Which technique allows the attacker to compromise additional cloud and on-premises identities without triggering standard cloud MFA prompts?
Select an answer to reveal the explanation
Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?
Select an answer to reveal the explanation
What is the primary risk associated with storing credentials in plain text within scripts or configuration files?
Select an answer to reveal the explanation
Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?
Select an answer to reveal the explanation
During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?
Select an answer to reveal the explanation
During an internal penetration test, you capture an NTLMv2 net-NTLM hash using LLMNR/NBT-NS poisoning. You attempt to crack the hash offline using Hashcat with a standard rockyou.txt wordlist, but the operation yields no plaintext. What is the most effective next step to recover the credentials given that the password complexity requirements were met?
Select an answer to reveal the explanation
You are performing a penetration test against a web server and want to identify the exact version of the HTTP service running on port 80. Which Nmap command should you use?
Select an answer to reveal the explanation
What is the primary benefit of using passive reconnaissance before initiating active scanning?
Select an answer to reveal the explanation
A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?
Select an answer to reveal the explanation
During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is the most effective post-exploitation technique for the operator to perform offline credential cracking against this captured artifact?
Select an answer to reveal the explanation
A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filtered'. Which technique can help determine whether these ports are actually open or filtered?
Select an answer to reveal the explanation
Answer all 20 questions to see your domain score breakdown
A structured study plan dramatically increases your chances of passing GPEN on the first attempt. The most effective approach combines reading the official GIAC documentation or a study guide, watching video explanations for difficult concepts, and then reinforcing everything with daily practice questions.
We recommend the following weekly structure for GPEN preparation:
Cover each GPEN domain systematically. Read the exam objectives, watch explanatory content, and do 10–20 practice questions per domain to test understanding as you go.
Run full 50–60 question mixed sessions daily. Review every wrong answer in detail. Identify which domains are consistently scoring below 70% and revisit those study materials.
Do 100–120 question timed sessions to simulate real exam conditions. Aim for consistent scores above 80% before booking your exam date. A score above 80% in practice typically translates to a passing GPEN score.
On exam day, the GPEN tests your ability to apply knowledge to realistic scenarios — not just recall definitions. This is why reading explanations and understanding the reasoning behind every answer matters more than simply grinding question volume. Use the high-count sessions (100, 120) in the final weeks as your confidence benchmark.
Questions
~298
On the real exam
Time limit
90 min
Official time limit
Passing score
700/1000
Scaled scoring
The GPEN exam uses a scaled scoring system — your raw score of correct answers is converted to a score out of 1000. A passing score of 700/1000 does not mean you need 70% of questions correct; the conversion accounts for question difficulty. Consistently scoring above 75–80% on practice tests puts you in a strong position to achieve 700/1000 on the real exam.
Scenario-based questions covering exam objectives with detailed answer explanations.
Yes. Courseiva provides free GIAC Penetration Tester practice questions with explanations across the official exam domains. Start with a quick practice test, then continue with topic-based practice, mock exams, missed-question review, bookmarked questions, weak-topic recommendations, and readiness tracking. No account required. Create a free account to unlock per-domain analytics and progress tracking across every certification on the platform. Courseiva is free forever, supported by advertising.
Every question is written against the official GPEN exam blueprint published by GIAC. Our questions follow the same wording style, scenario complexity, and answer structure as the actual exam. They are original questions — not brain dumps — so you learn the underlying concepts and reasoning, not just memorised answers. Candidates who study with brain dumps often pass but have no transferable knowledge; Courseiva questions make you genuinely competent.
Most candidates who pass GPEN on their first attempt do 30–60 questions per day. Use the Quick 10 session for daily warm-ups when you are short on time. On study days, run a 50 or 60-question session to build stamina. Reserve 100 and 120-question sessions for the final two weeks when you want to simulate real exam conditions and benchmark your readiness.
The GPEN covers 15 domains: Attacking Password Hashes, Password Attacks and Formats, Scanning and Host Discovery, Metasploit, Vulnerability Scanning, Kerberos Attacks, Reconnaissance, Command and Control, Exploitation Fundamentals, Azure AD Integration, Domain Escalation and Persistence, Azure Apps and Attacks, Escalation and Exploitation, Advanced Password Attacks, Pen Test Planning. Each domain carries a different weight, so allocate your study time accordingly. The highest-weighted domains — Attacking Password Hashes and Password Attacks and Formats — should receive the most attention.
Exam dumps are memorised question-and-answer lists taken from actual exam papers, often obtained illegally and shared without GIAC's authorisation. Using them violates your NDA and GIAC's certification agreement, and can result in certification revocation. Courseiva questions are original — AI-assisted, checked against the official exam objectives, and published under the editorial oversight of an engineer with 12+ years' experience. They test the same knowledge areas using new scenarios and wording. You learn the material, not just the answers.
Per-domain analytics, spaced repetition, daily challenges — and every other certification on the platform.
Sign Up FreeFree forever · Every certification included